Framework mapping
EUQA is not a single-regulation product. The same five controls produce the evidence that multiple AI governance frameworks ask for, which matters if you operate in more than one market.
Frameworks covered
- EU AI Act
- ISO/IEC 42001
- NIST AI Risk Management Framework
- OECD AI Principles
- Council of Europe Framework Convention on AI
- UK pro-innovation AI framework
- Colorado AI Act (US)
- Canada AIDA / voluntary code
- Singapore Model AI Governance Framework
- ISO/IEC 23894 AI risk guidance
Beyond the AI Act
The AI Act is an EU-wide framework, but national authorities enforce it alongside existing national rules on employment, equality, data protection and consumer protection. If you operate across several countries, you may need to account for more than the AI Act alone.
Timing under the EU AI Act
- Already applicable: AI literacy obligations have applied since 2 February 2025. Firms using AI should be able to show what measures they have taken to help relevant staff use it responsibly.
- Applicable now: From 2 August 2026, specific AI interactions and certain AI-generated or manipulated content must be disclosed or marked. Whether that applies depends on how the system is used. National authorities also begin exercising relevant enforcement powers from this date.
- Preparation window: The main requirements for standalone high-risk systems are scheduled to apply from 2 December 2027. Systems used to analyse, filter or evaluate people in an employment context fall within the high-risk employment category, subject to the relevant legal conditions.